{"id":"CVE-2016-10517","details":"networking.c in Redis before 3.2.7 allows \"Cross Protocol Scripting\" because it lacks a check for POST and Host: strings, which are not valid in the Redis protocol (but commonly occur when an attack triggers an HTTP request to the Redis TCP port).","modified":"2026-08-07T14:48:13.045341Z","published":"2017-10-24T18:29:00.197Z","related":["SUSE-OU-2020:3291-1","openSUSE-SU-2017:2984-1","openSUSE-SU-2017:2994-1","openSUSE-SU-2024:11299-1"],"references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/101572"},{"type":"REPORT","url":"https://github.com/antirez/redis/commit/874804da0c014a7d704b3d285aa500098a931f50"},{"type":"REPORT","url":"https://raw.githubusercontent.com/antirez/redis/3.2/00-RELEASENOTES"},{"type":"REPORT","url":"https://www.reddit.com/r/redis/comments/5r8wxn/redis_327_is_out_important_security_fixes_inside/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/antirez/redis","events":[{"introduced":"0"},{"fixed":"874804da0c014a7d704b3d285aa500098a931f50"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"vanir_signatures":[{"signature_version":"v1","source":"https://github.com/antirez/redis/commit/874804da0c014a7d704b3d285aa500098a931f50","target":{"file":"src/server.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["124880604520077166671741876553448855320","17607989238585627192006328325640026296","316040378880908604113778517788260677767","93458149514543909809984600211885125528"]},"id":"CVE-2016-10517-34fc378b","signature_type":"Line"},{"signature_version":"v1","source":"https://github.com/antirez/redis/commit/874804da0c014a7d704b3d285aa500098a931f50","target":{"file":"src/server.h"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["293441393269233123675708999680469895646","70362983986487224871491241103974749383","205390326808090795749215624981622578027","304632248323533289008649620454653853583"]},"id":"CVE-2016-10517-8b5e18a9","signature_type":"Line"},{"id":"CVE-2016-10517-c30ff40c","signature_type":"Line","signature_version":"v1","source":"https://github.com/antirez/redis/commit/874804da0c014a7d704b3d285aa500098a931f50","target":{"file":"src/networking.c"},"deprecated":false,"digest":{"line_hashes":["163148284592519125185901164272060612753","70451653832058093279536878907119473300","215185346124952849263144259165636240912","100079807825566757584135242790465355990","199479240253159866632050854038291740593","245006625046125700008417689478308844302","96178466864819807631888675772326466251"],"threshold":0.9}},{"digest":{"function_hash":"152124302612145123004825358630729190358","length":876},"id":"CVE-2016-10517-f00326f7","signature_type":"Function","signature_version":"v1","source":"https://github.com/antirez/redis/commit/874804da0c014a7d704b3d285aa500098a931f50","target":{"function":"processInputBuffer","file":"src/networking.c"},"deprecated":false}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-10517.json","vanir_signatures_modified":"2026-08-07T14:48:13Z"}},{"ranges":[{"type":"GIT","repo":"https://github.com/redis/redis","events":[{"introduced":"0"},{"fixed":"af12f8ec3cf13a10e4039547a81cf5f163937063"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"3.2.7"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:redislabs:redis:*:*:*:*:*:*:*:*"}}],"versions":["3.2.6","3.2.5","3.2.4","3.2.3","3.2.2","3.2.1","3.2.0","3.2.0-rc3","3.2.0-rc2","3.2-rc1","2.3-alpha0","2.2.0-rc1","2.2-alpha6","2.2-alpha5","2.2-alpha4","2.2-alpha3","2.2-alpha2","2.2-alpha1","2.2-alpha0","v2.0.0-rc1","v2.1.1-watch","v1.3.11","v1.3.10","v1.3.9","v1.3.8","v1.3.7","1.3.6","vm-playpen"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-10517.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N"}]}